Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
478cf312 by Salvatore Bonaccorso at 2026-08-27T22:31:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37,127 +37,127 @@ CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2 
(fixed in 3.10.3) conta
        - nltk 3.10.3-1
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g
 CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost 
parameters in  ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81720 (openssl_encrypt before 1.4.9 fails to validate the memory_cost 
paramet ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81719 (openssl_encrypt before 1.4.9 executes untrusted third-party 
plugins wi ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81718 (openssl_encrypt versions before 1.4.9 use under-parameterized 
PBKDF2-H ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81717 (openssl_encrypt (pip package openssl-encrypt) before 1.4.9 
contains tw ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81716 (openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 
contain a ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81715 (openssl_encrypt (pip package openssl-encrypt) versions <= 
1.4.8 do not ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81714 (openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use 
suffix-to ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81707 (openssl_encrypt before 1.4.9 fails to sanitize the email field 
of impo ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81706 (openssl_encrypt before 1.4.9 fails to prevent namespace 
collisions bet ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81705 (openssl-encrypt before 1.4.9 fails to redact the file password 
in its  ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81704 (openssl_encrypt versions before 1.4.9 contain a weak key 
derivation vu ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81703 (openssl_encrypt versions before 1.4.9 fail to validate 
encryption stat ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81702 (openssl_encrypt before 1.4.9 fails to re-derive and validate 
fingerpri ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81701 (openssl_encrypt versions before 1.4.9 use a denylist to 
identify trust ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81700 (openssl_encrypt versions before 1.4.9 contain a signature 
verification ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81699 (openssl_encrypt versions before 1.4.9 fail to properly 
validate key de ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81698 (openssl_encrypt versions before 1.4.9 contain a shell 
injection vulner ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81697 (openssl_encrypt (pip package openssl-encrypt) versions <= 
1.4.8 contai ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81696 (openssl_encrypt versions before 1.4.9 fail to sanitize 
terminal contro ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81695 (openssl_encrypt versions before 1.4.9 fail to escape 
attacker-controll ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81694 (openssl-encrypt (pip package, versions <= 1.4.8) fails to 
sanitize fil ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81693 (openssl_encrypt before 1.4.9 fails to validate the total field 
from QR ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81692 (openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and 
earlier fail ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81691 (openssl_encrypt versions before 1.4.9 fail to validate server 
URLs in  ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81690 (openssl-encrypt (pip package) before 1.4.9 contains a 
symlink-followin ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81689 (openssl_encrypt versions before 1.4.9 derive the remote-pepper 
wrap ke ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81688 (openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 
hash of ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81687 (openssl_encrypt versions before 1.4.9 fail to enforce a time 
ceiling o ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81686 (openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus 
crypto s ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81685 (openssl_encrypt versions before 1.4.9 fail to sanitize 
recovery-slot m ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81684 (In openssl_encrypt (pip package openssl-encrypt) versions <= 
1.4.8, th ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81683 (openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 
and earli ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81682 (openssl_encrypt versions before 1.4.9 contain an insecure file 
permiss ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81681 (openssl_encrypt (pip package openssl-encrypt) versions <= 
1.4.8 advert ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81680 (openssl_encrypt versions before 1.4.9 fail to authenticate 
recovery-sl ...)
-       TODO: check
+       NOT-FOR-US: OpenSSL Encrypt
 CVE-2026-81679 (OpenRemote versions before 1.28.0 contain a cross-realm 
information di ...)
-       TODO: check
+       NOT-FOR-US: OpenRemote
 CVE-2026-81678 (AVideo before 24.0 contains a server-side request forgery 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: WWBN AVideo
 CVE-2026-81677 (The \u2018/ws/apiprensa/getVideo\u2019 endpoint is vulnerable 
to SQL i ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81676 (A vulnerability in the endpoint 
\u2018/ws/apitribuna/ultimosVideos\u20 ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81675 (The endpoint \u2018/ws/apiprensa/getVideoUltimasSeccion\u2019 
contains ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81674 (The endpoint \u2018/ws/apiprensa/getVideoNextPrev\u2019 is 
vulnerable  ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81673 (The \u2018/ws/apitribuna/setVisita\u2019 endpoint is 
vulnerable to SQL ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81672 (SQL injection vulnerability in the 
\u2018/ws/apiprensa/getVideoSubcana ...)
-       TODO: check
+       NOT-FOR-US: TOOOLS iSquad
 CVE-2026-81668 (A flaw was found in Katello where the Content View Filter 
Rules API do ...)
-       TODO: check
+       NOT-FOR-US: Katello
 CVE-2026-81664 (The OpenFaaS gateway registers GET /system/telemetry in 
gateway/main.g ...)
-       TODO: check
+       NOT-FOR-US: OpenFaaS gateway
 CVE-2026-81662 (Affected versions of Flowintel improperly trust configuration 
keys sup ...)
-       TODO: check
+       NOT-FOR-US: Flowintel
 CVE-2026-81659 (Affected versions of Flowintel allow attacker-controlled note 
content  ...)
-       TODO: check
+       NOT-FOR-US: Flowintel
 CVE-2026-81658 (A flaw was found in Foreman. The template revision endpoint 
does not e ...)
        TODO: check
 CVE-2026-81625 (A remote attacker with user privileges may use a malicious or 
compromi ...)
-       TODO: check
+       NOT-FOR-US: Greenbone
 CVE-2026-81581 (Improper validation of memory boundaries in WibuKey64.sys of 
WibuKey u ...)
-       TODO: check
+       NOT-FOR-US: WibuKey
 CVE-2026-81579 (In WibuKey for Windows before version 6.71, an untrusted 
pointer deref ...)
-       TODO: check
+       NOT-FOR-US: WibuKey
 CVE-2026-81576 (If configured as a server, CodeMeter Runtime before versions 
8.41a and ...)
-       TODO: check
+       NOT-FOR-US: CodeMeter Runtime
 CVE-2026-81575 (If configured as a server, CodeMeter Runtime before versions 
8.41a and ...)
-       TODO: check
+       NOT-FOR-US: CodeMeter Runtime
 CVE-2026-81574 (In CodeMeter Runtime before versions 8.41a and 9.10, the 
logger does n ...)
-       TODO: check
+       NOT-FOR-US: CodeMeter Runtime
 CVE-2026-81573 (If CodeMeter Runtime before 8.41a or 9.10 is configured as a 
server, t ...)
-       TODO: check
+       NOT-FOR-US: CodeMeter Runtime
 CVE-2026-81572 (cmu.exe --create-io --file C: creates a predictable temporary 
file und ...)
-       TODO: check
+       NOT-FOR-US: Wibu
 CVE-2026-81562 (A security flaw has been discovered in AlexGladkov 
claude-in-mobile 3. ...)
-       TODO: check
+       NOT-FOR-US: AlexGladkov claude-in-mobile
 CVE-2026-81560 (A vulnerability was identified in blackms aistack up to 1.6.1. 
Affecte ...)
-       TODO: check
+       NOT-FOR-US: blackms aistack
 CVE-2026-81335 (Baserow dispatches an Application Builder data source without 
acting o ...)
-       TODO: check
+       NOT-FOR-US: Baserow
 CVE-2026-81334 (darknet subscripts its layer array with an index taken from a 
configur ...)
-       TODO: check
+       NOT-FOR-US: darknet
 CVE-2026-81279 (Subscriber Broken Access Control in Push Notification for Post 
and Bud ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81277 (Contributor SQL Injection in Suggestion Engine for WooCommerce 
<= 2.0. ...)
@@ -173,15 +173,15 @@ CVE-2026-81272 (Editor Broken Access Control in 
FluentPlayer Pro <= 1.3.2 versio
 CVE-2026-81271 (Unauthenticated Cross Site Request Forgery (CSRF) in 
GeoDirectory <= 2 ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81102 (The Dash MCP server bound its listener to the loopback address 
but nev ...)
-       TODO: check
+       NOT-FOR-US: Dash MCP server
 CVE-2026-81101 (The configure command accepted any endpoint URL and stored it 
beside t ...)
-       TODO: check
+       NOT-FOR-US: Airtable
 CVE-2026-81100 (tiger-gh-mcp-server started its MCP HTTP transport without 
enabling th ...)
-       TODO: check
+       NOT-FOR-US: tiger-gh-mcp-server
 CVE-2026-81099 (tiger-slack started its MCP HTTP transport without enabling 
the host a ...)
-       TODO: check
+       NOT-FOR-US: tiger-slack
 CVE-2026-81098 (The Telnyx MCP server exposed its HTTP transport on every 
interface an ...)
-       TODO: check
+       NOT-FOR-US: Telnyx MCP server
 CVE-2026-81097 (The execute_ruby tool is documented as a read-only Ruby 
sandbox and is ...)
        TODO: check
 CVE-2026-81096 (ToolUniverse ran caller-supplied Python inside a sandbox that 
could be ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/478cf312f038366a565ae4d04fb6ff542a5ad5b6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/478cf312f038366a565ae4d04fb6ff542a5ad5b6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to